Junglewise Threat Intelligence

CVE-2026-84766: WordPress FluentBooking Pro authentication bypass

CVE-2026-84766 · Severity: medium · CVSS 5.9 · Published 2026-09-03

Vendors: WP ManageNinja LLC.

Executive brief

FluentBooking Pro is a WordPress plugin that manages bookings and reservations for WordPress websites. An unauthenticated attacker can bypass security checks in affected versions, potentially gaining unauthorized access to booking functions or administrative features without proper login credentials.

Technical details

The vulnerability is classified as an insecure design flaw that allows attackers to circumvent authentication or authorization checks in FluentBooking Pro versions up to 2.2.1. The bypass is unauthenticated, meaning no login credentials or special privileges are required to exploit it. An attacker can leverage this to access protected booking operations or administrative functions. The vulnerability has been patched in version 2.3.0 and later.

Affected products

  • WP ManageNinja LLC FluentBooking Pro <= 2.2.1

Timeline

  • 2026-09-03: disclosed
  • 2026-09-03: patched: Version 2.3.0 or later

References

Related threats